CVE-2026-4134 is a privilege escalation vulnerability discovered in Lenovo Software Fix that allows authenticated local users to execute code with elevated privileges during the software installation process. The vulnerability requires user interaction but presents a significant risk to systems running affected Lenovo products. The vulnerability carries a CVSS score of 7.3 (HIGH) with a local attack vector, low complexity, and low privilege requirements. Successful exploitation results in high confidentiality, integrity, and availability impact, potentially allowing attackers to fully compromise affected systems through code execution with elevated permissions. The vulnerability currently shows no evidence of active exploitation in the wild, with an EPSS score of 0.00014 indicating minimal real-world exploitation probability. No public exploit code is currently available, and community attention remains low, as evidenced by the vulnerability's inactive status on threat tracking lists and its absence from the Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lenovo | Software Fix | >= 0, < 7.5.5.19CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.